logo

Ensuring Data Protection for Third Parties: Best Practices | UpGuard

ID: 9fb9709f-865a-5178-8e3c-57a380a5632d

STIX ID: report--9fb9709f-865a-5178-8e3c-57a380a5632d

Feed Name: UpGuard Blog

Date Published: 2025-01-17

Date Updated: 2026-05-01

...
...

This is a guidance document on third-party data risk and vendor risk management: it outlines the risks introduced when external providers handle sensitive data, summarizes relevant legal and regulatory obligations (GDPR, CCPA, HIPAA), and provides best practices and a step-by-step approach to build a Vendor Risk Management program (vendor selection, assessments, controls, monitoring, encryption, audits, staff training, and incident response). It cites the 2013 Target third-party breach as an example but does not present a new incident analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.